Security Operations Center (SOC)
Detect and stop attacks before damage occurs. Our Security Operations Center monitors your IT and OT infrastructure.
What you gain
You get professional cyber security without having to build a security team of your own. We monitor your systems continuously, detect anomalies and respond according to established procedures. Monitoring covers both IT and OT, which includes the technology on your production floor.
The reason for this effort lies in the nature of the attacks. Cyber attacks run around the clock. They run quietly and often remain unnoticed for a long time. By the time something is noticed, the damage has usually already been done. The traces are there in the logs of your systems. But nobody brings them together. No IT team can manage this alongside its day-to-day work. This is exactly the work a SOC takes on. It collects the security events from your infrastructure, relates them to one another and separates the genuine incident from the normal noise of daily operations.
A SOC is therefore more than a virus scanner. A virus scanner makes its decision on a single device. The SOC sees all devices together. Only then do patterns become visible that look harmless on an individual machine.
The SOC is not the NOC. The Network Operations Center ensures operations and availability. The SOC ensures security, which means attack detection and defence. Both work on the same systems, but with different questions. The NOC asks whether a system is running. The SOC asks whether somebody is attacking it.
Our customers are KRITIS operators (operators of critical infrastructure), municipal utilities, hospitals, mechanical engineering companies, industrial businesses and mid-sized manufacturers. In other words, organisations where a security incident affects not only data, but production or public supply. inducio works from Traunstein.
On this page
The three services of the SOC:
Threat detection and responseEndpoint ProtectionVulnerability Assessment (VAS)
Plus the technology behind them:
Threat detection and response
We detect attacks on your IT and OT infrastructure and respond to them. This is the core service of the SOC.
An attack does not announce itself. At the beginning it looks like normal operations. An account logs in at night. A server talks to an address it has never needed before. A service appears that nobody set up there. Each event on its own is harmless. Together they form a pattern.
Our SIEM makes this connection. The security events from your systems come together in one place and are related to one another there. A single failed login is meaningless on its own. Many failed logins, followed by a successful one and a new service on the same server, are an incident. No individual system sees this connection. It only emerges through correlation.
There is also detection at the behavioural level. EDR works on the endpoints, NDR in the network traffic. Neither looks for known files, both look for unusual behaviour. That means processes that do something they should not be doing there. And connections that did not exist in your network before.
Detection alone is not enough. An alert that nobody responds to is just one more entry. The response is therefore part of the service. We examine the finding, classify it and initiate the agreed steps according to established incident response procedures. Recurring steps run automatically, so the first few minutes are not spent on manual work. The decisions that require judgement are made by people.
Detection also covers the security technology itself. The ongoing operation of your firewall sits with the NOC under Firewall Service. Attacks directed against that firewall or passing through it are a matter for the SOC.
For operators of critical infrastructure this is not optional. The BSI requires a System zur Angriffserkennung (SzA), a system for attack detection. We implement it and operate it. More on this on the page Critical Infrastructures.
Endpoint Protection
We protect every single device, from the notebook to the server. That way a single click by an employee does not turn into a fire across the whole network.
The endpoint is the most common point of entry. Somebody opens an attachment that looks like an invoice. This happens to attentive people too, and it happens precisely when there is a lot to do. From that one notebook it moves on into the network. This is why the first detection stage sits here.
The basis is up-to-date virus protection on all endpoints, currently G DATA. We keep this selection aligned with the threat situation. On top of that sits Endpoint Detection and Response with advanced threat detection and automated response.
The difference between the two matters. Classic virus protection detects what is already known and blocks it immediately. Endpoint Detection and Response looks at behaviour. It sees the chain and not the individual file. An attachment starts a script. The script downloads further code. The code accesses login credentials. Each step on its own can be legitimate. The chain is not. A program that starts encrypting files one after another is noticed even when the malware is new and unknown.
We monitor these alerts and raise the alarm in the event of security incidents. The alerts do not stop at the device. They flow into the same analysis as the remaining security events and are brought together there with the rest of your infrastructure. The data produces reports that you can use as compliance evidence.
Endpoint Protection is not Endpoint Management. Protection defends the device against threats and therefore belongs in the SOC. Endpoint Management administers the device, distributes software, applies updates and keeps the configuration consistent. It is based on baramundi and belongs in the NOC as an operational service. The two interlock, because a well-maintained device offers less attack surface. The tasks are still kept separate, because they answer different questions.
Vulnerability Assessment (VAS)
We continuously search for vulnerabilities in your systems and tell you which ones you need to close first. We look at this from the network perspective. The second part is the actual benefit.
Testing is done over the network. No additional software on the individual devices is required for this. That sounds like a technical detail. In a production environment it decides whether any testing happens at all. On a machine controller, a medical device or an older production system, it is usually impossible to install anything. The manufacturer does not permit it. Certification or warranty depends on it. Or the system is simply too old.
This is exactly where a blind spot otherwise appears. Anyone who only tests where additional software is allowed to run is testing the office IT. What gets overlooked are precisely those systems that run the longest and are the hardest to replace. Such installations often run longer than their manufacturer's support. There are then no more updates for their vulnerabilities, while those vulnerabilities are publicly documented. Over the network, everything that carries an IP address comes into view. Including the printer, the controller and the legacy system.
The broader view brings a second problem with it. The more systems become visible, the longer the list becomes. A vulnerability scan is quickly done. Every entry carries a criticality rating, and many of them are rated high. Every IT manager can get this list anywhere today. The problem is not that it is missing. The problem is that nobody works through it.
The reason is simple. A small IT department has little time alongside day-to-day work for tasks that go beyond the normal update cycle. A very long list is therefore unmanageable. If everything is important, nothing is important. The list ends up in the archive, and the environment remains as vulnerable as before. At the next scan the list is longer. A vulnerability list without prioritisation does not increase security. It only increases the amount of paperwork.
We therefore prioritise according to the actual probability of exploitation and not according to the length of the list. The basis for this is EPSS. This value estimates how likely it is that a particular vulnerability will really be attacked. That is a different question from the one about technical severity. Severity describes how bad a successful exploitation would be. It says nothing about whether anyone will even attempt it.
In practice the difference is considerable. Some vulnerabilities with high technical severity are so laborious to exploit that in reality it does not happen. Others with medium severity are tried out on a massive scale. Anyone working strictly by severity rating patches the first group and leaves the second one open.
What you get is therefore not a list, but an order of priority. We scan regularly, assess the findings and tell you, with reasons, what should be closed first. The rest does not disappear. It moves back in the queue and moves forward as soon as the situation changes. Your team can therefore work from top to bottom and reach an end. The next run shows what has been closed and what has newly been added.
Vulnerability Assessment is a service provided by inducio. The technical basis is the Central Operations Dashboard (COD), which keeps a continuous record of your network devices anyway. Finding and device therefore sit in one place. The assessment and the recommendation come from us. A probability value does not know your environment. It does not know which system carries your operations and which installation halts production if it fails. We contribute this part, because we know your infrastructure.
What we know about open vulnerabilities feeds into the assessment of an incident. An open vulnerability on a system that is currently behaving suspiciously changes the assessment in threat detection.
The platforms
Two platforms sit behind the three services. You do not have to buy, operate or use either of them. We bring them with us and operate them as part of the service.
Security data is otherwise scattered. The firewall has its log, the virus scanner has its own, the servers have another. Anyone who wants to trace an incident opens three systems and compares timestamps by hand. That takes a long time. Time is exactly what you do not have in such a situation.
ZephSense is our own security platform and a product of inducio GmbH. Detection and response are built on it. The SIEM collects the events from all connected systems and puts them into context. EDR and NDR provide behavioural detection on the endpoints and in the network traffic. SOAR carries out the recurring response steps automatically. The advantage lies in the shared data basis. Endpoint and network traffic come together in one analysis. This makes it visible in a single step whether a suspicious process also leaves traces in the network traffic. For operators of critical infrastructure, ZephSense is at the same time a technical foundation for a System zur Angriffserkennung (a system for attack detection) in line with BSI requirements.
The Central Operations Dashboard (COD) carries the Vulnerability Assessment. It is a vendor-independent platform from extocode GmbH and keeps a continuous record of your network devices anyway. This is precisely why the vulnerability analysis sits there. The same platform also carries Monitoring in daily operations.
You will find all technical details at zephsense.cloud and at Central Operations Dashboard.
How we work
The procedure is the same for all components.
Availability. We monitor and analyse your IT and OT infrastructure around the clock, 24 hours a day and seven days a week. Security events are assessed continuously and not only reviewed on the next working day. Attacks do not keep office hours. Neither does our monitoring.
Reporting. You receive dashboards and reports on the security situation, on the status of vulnerabilities and on the incidents handled. Compliance management is included as well. The reports are prepared in such a way that you can use them to demonstrate to management, regulators and auditors what you are doing.
Point of contact. Reports and queries go through one central point of contact. You do not have to find the right engineer. You report once. The route is the same as for the 24/7 support of the NOC.
Frequently asked questions
What is the difference between SOC and NOC?
The SOC ensures security and defence against attacks. The NOC ensures operations and availability. Two examples make the boundary clear. An attack on your firewall is detected by the SOC. That same firewall is operated, patched and hardened in the NOC under Firewall Service. We protect your devices in the SOC under Endpoint Protection. They are administered and updated in the NOC under Endpoint Management.
What is ZephSense?
ZephSense is our security platform for SIEM, EDR/NDR and SOAR. Detection and response in the SOC are built on it. The Vulnerability Assessment runs on the Central Operations Dashboard, because it looks at vulnerabilities from the network perspective. More at zephsense.cloud.
What is a System zur Angriffserkennung (SzA)?
A solution required by the BSI that detects and reports attacks. In English it is a system for attack detection. Operators of critical infrastructure need one. We implement it and operate it, among other things with ZephSense.
Already a customer?
The complete service descriptions for the individual components are available in your customer portal. They set out in detail what is included in each service and what is not. You will find them after logging in under “My Account”.
Go to the service descriptions
Request the SOC service
Tell us which systems you operate and where your need for protection is greatest. We will look at your environment and tell you what connecting to our SOC would mean for you.